OESA-2026-4051

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4051
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4051.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4051
Upstream
CVE (2)
Published
2026-09-25T01:27:41Z
Modified
2026-09-25T01:45:06Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
hdf5 security update
Details

HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.

Security Fix(es):

A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.(CVE-2025-2915)

H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.(CVE-2026-19025)

Database specific
{
    "severity":  "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP4 / hdf5

Package

Name
hdf5
Purl
pkg:rpm/openEuler/hdf5&distro=openEuler-24.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.5-7.oe2403sp4

Ecosystem specific

{
    "aarch64":  [
        "hdf5-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-debuginfo-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-debugsource-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-devel-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-mpich-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-mpich-devel-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-mpich-static-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-openmpi-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-openmpi-devel-1.14.5-7.oe2403sp4.aarch64.rpm",
        "hdf5-openmpi-static-1.14.5-7.oe2403sp4.aarch64.rpm"
    ],
    "src":  [
        "hdf5-1.14.5-7.oe2403sp4.src.rpm"
    ],
    "x86_64":  [
        "hdf5-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-debuginfo-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-debugsource-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-devel-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-mpich-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-mpich-devel-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-mpich-static-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-openmpi-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-openmpi-devel-1.14.5-7.oe2403sp4.x86_64.rpm",
        "hdf5-openmpi-static-1.14.5-7.oe2403sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4051.json"